this post was submitted on 22 Nov 2023
498 points (100.0% liked)

Technology

70285 readers
2813 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 2 points 2 years ago (1 children)

Which just had some leaks about how insecure it is.

Windows Hello didn't. The hardware wasn't implemented correctly allowing the authentication to be bypassed. You misunderstood the issue here

They sync shit using iCloud...

They sync the public key with iCloud, not the private key. You misunderstood how it works.

It doesn't matter how many keys deep you have to go.

There is no "keys deep" there is a public/private key pair that authenticates a single device with a single account. You have misunderstood how a local key store works.

The compromised item is already obtained when you obtained the device.

Which means someone trying to access my account requires physical access to my device. Passwords, no matter how strong leave you open to remote attack.

Can you tell me the process to revoke the private key from your fingerprint reader on your phone?

Open the authencator app and remove the account. Or uninstall the authenticator app. Or delete your local phone account. Or factory reset if you want to go nuclear.

Alternatively if you lost your phone, go to the account online. Browse to the security section and delete the device from the list. Most services have the ability to sign out remotely. All that's doing is revoking the key. The phone doesn't have to do anything. The fact you think something needs change in the "blob" shows you do not understand how encryption works.

If I were to bump into you, and lift your phone.

Again physical access, not remote access. Much smaller attack vector than a password.

It puts all the power into another companies hands... and takes ALL of it out of yours.

You think passwords take power from the company that stores your passwords remotely? You have no idea how they are storing that password. You don't have to trust the company, you just have to trust the open standard these companies are implementing and that public/private key encryption is the standard used to secure the entire Internet.

Also, whats more likely... that you break a device or that a user CANNOT learn how to use a password manager?

Virtually no one uses a password manager. It's too much hassle.